Lucene search

K

Poll Scm Security Vulnerabilities

cve
cve

CVE-2017-1000093

Poll SCM Plugin was not requiring requests to its API be sent via POST, thereby opening itself to Cross-Site Request Forgery attacks. This allowed attackers to initiate polling of projects with a known name. While Jenkins in general does not consider polling to be a protection-worthy action as...

8.8CVSS

8.5AI Score

0.001EPSS

2017-10-05 01:29 AM
38